Junglewise Threat Intelligence

CVE-2026-34365: InvoiceShelf SSRF in Estimate PDF generation module

CVE-2026-34365 · Severity: high · CVSS 7.6 · Published 2026-03-31

Technologies: Invoiceshelf. Vendors: Invoiceshelf.

Executive brief

InvoiceShelf, an open-source platform for managing business expenses and invoices, contains a security flaw in its estimate generation system. An attacker with administrative access can inject malicious code into the 'Notes' field of an estimate, causing the server to make unauthorized requests to internal or external systems when a PDF is generated. This could allow an attacker to scan internal networks, access sensitive cloud metadata, or potentially read private files on the server.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf prior to version 2.2.0. The application passes user-supplied HTML from the estimate 'Notes' field directly to the Dompdf rendering library without sanitization. When a PDF is previewed or viewed via the customer endpoint, Dompdf fetches any remote resources (such as images or stylesheets) referenced in the markup. This allows an authenticated attacker to perform internal network reconnaissance, access cloud metadata endpoints, or potentially read local files via the file:// wrapper. The issue is present in the Estimate PDF generation module and affects endpoints including /api/v1/estimates/{estimate}/send and /estimates/pdf/{unique_hash}. A patch is available in version 2.2.0.

Affected products

  • InvoiceShelf InvoiceShelf < 2.2.0

Timeline

  • 2026-03-24: patched: Version 2.2.0 released
  • 2026-03-27: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE published to NVD

References

Related threats